Technology Law
Cybersecurity Law & the Cybercrimes Act
Understanding the criminal offences, mandatory reporting obligations, and compliance requirements under South Africa's cybercrime legislation
Written by
Martin Kotze
Attorney, Conveyancer & Notary Public
Last reviewed:
Contents
The Cybercrimes Act 19 of 2020 represents South Africa's most significant legislative response to the growing threat of cybercrime. Signed into law by the President and with its core provisions brought into operation, the Act creates a comprehensive criminal framework for cyber offences, provides (under section 54, which is not yet in force) for breach reporting obligations on electronic communications service providers and financial institutions, and establishes structures for international cooperation in the investigation and prosecution of cybercrime.
For businesses operating in the digital economy, the Act has practical implications that go well beyond criminal law. It intersects with software and technology law more broadly, particularly in relation to data protection, contractual obligations in SaaS agreements, and the cybersecurity measures that businesses are expected to implement as a matter of course.
Overview of the Cybercrimes Act 19 of 2020
The Cybercrimes Act replaced the outdated and fragmented provisions of the Electronic Communications and Transactions Act 25 of 2002 (ECTA) that dealt with cybercrime. While ECTA contained some provisions addressing unauthorised access and data interference, they were widely regarded as inadequate to address the scale and sophistication of modern cybercrime. The Cybercrimes Act consolidates and expands the criminal law framework, creating new offences, prescribing harsher penalties, and establishing procedural mechanisms for the investigation and prosecution of cyber offences.
The Act applies to any offence committed within the Republic of South Africa, but also has extraterritorial application where a South African citizen commits a cybercrime outside the Republic, or where the offence affects a person, entity, or computer system located within South Africa. This extraterritorial reach is particularly relevant for businesses with cross-border operations and cloud infrastructure hosted outside South Africa's borders.
The Act also establishes structures for the reporting and investigation of cybercrimes. It designates the South African Police Service (SAPS) as the primary investigative authority and establishes a 24/7 point of contact for international cooperation, in line with South Africa's obligations under the Budapest Convention on Cybercrime, which South Africa has signed but not yet ratified.
Key Offences Under the Act
The Cybercrimes Act creates a range of offences that cover the full spectrum of cybercriminal activity. Understanding these offences is important not only for potential perpetrators, but for businesses that may be victims, that may need to report incidents, or that may face liability for inadequate security measures.
Unlawful Access (Section 2)
Any person who unlawfully and intentionally accesses a computer system or data without authority or permission commits an offence. This covers traditional hacking — gaining access to a system by bypassing authentication controls — as well as situations where a person exceeds the scope of their authorised access. An employee who accesses confidential business data stored on a system they are not authorised to use could fall within the scope of this provision.
Unlawful Interception of Data (Section 3)
The unlawful and intentional interception of data, including communications data, within a computer system constitutes an offence. This provision targets activities such as packet sniffing, man-in-the-middle attacks, and the installation of keyloggers or spyware. It applies regardless of whether the intercepted data is encrypted or unencrypted.
Hacking Tools, Interference and Passwords (Sections 4–7)
Section 4 criminalises unlawful acts in respect of software or hardware tools used to commit cyber offences. Section 5 targets unlawful interference with data or a computer program — the provision under which ransomware-type conduct, such as encrypting or corrupting a victim's data, is prosecuted. Section 6 covers unlawful interference with a computer data storage medium or computer system, and section 7 criminalises the unlawful acquisition, possession or use of passwords, access codes or similar devices.
Cyber Fraud (Section 8)
Cyber fraud is committed by any person who unlawfully and with intent to defraud makes a misrepresentation by means of data or a computer program, or by interfering with data or a computer program, causing actual or potential prejudice to another person. This provision covers phishing attacks, business email compromise (BEC) schemes, fake websites designed to harvest credentials, and any other form of online fraud. It significantly expands on the common law crime of fraud by addressing the digital mechanisms through which modern fraud is committed.
Cyber Forgery and Uttering (Section 9)
Cyber forgery is committed by any person who unlawfully and with intent to defraud creates false data or a false computer program to the actual or potential prejudice of another person. Uttering — passing off that false data or program as genuine — is a separate offence under the same section. These are the digital counterparts of the common-law crimes of forgery and uttering, covering conduct such as fabricated electronic invoices, falsified digital records, and spoofed documents.
Cyber Extortion (Section 10)
Any person who unlawfully and intentionally commits or threatens to commit an offence of interception, interference with data, a computer program, a storage medium or a computer system, or unlawful use of passwords or access codes, in order to obtain an advantage from another person or to compel another person to do or not do something, commits the offence of cyber extortion. This provision is directly relevant to ransomware attacks, where criminals encrypt a victim's data and demand payment for its release. The Act treats both the encryption of data and the demand for ransom as criminal acts.
Malicious Communications (Section 14)
The Act creates an offence of distributing data messages that are inherently harmful, including messages that incite damage to property or violence, or that threaten persons with damage to property or violence. While this provision is primarily aimed at combating online harassment and threats, it has broader implications for businesses that operate social media platforms, messaging services, or any digital platform through which users can communicate.
Attempting, Aiding, and Abetting
The Act criminalises not only the commission of cyber offences, but also their attempted commission. Any person who aids, abets, induces, incites, instigates, instructs, commands, or procures another person to commit an offence under the Act is also guilty of an offence. Furthermore, the acquisition, possession, provision, or receipt of any article — including hardware, software, or passwords — for the purpose of committing an offence is itself criminal.
Reporting Under Section 54 (Not Yet in Force)
Important: Section 54 was excluded from the Act’s 1 December 2021 commencement and is not yet in force; it will require ECSPs and financial institutions to report qualifying offences to the SAPS (within 72 hours, on pain of a fine of up to R50,000) only once the President proclaims a commencement date. Until then, the only breach-notification duty currently in force is POPIA section 22. The description below sets out what section 54 will require once it is proclaimed.
Once in force, one of the most significant operational obligations under the Cybercrimes Act will be the section 54 reporting duty on electronic communications service providers (ECSPs) and financial institutions. An ECSP or financial institution that becomes aware that its own electronic communications service or network is involved in the commission of an offence in the categories determined under section 54(2) will have to report the offence to the SAPS in the prescribed form — without undue delay and, where feasible, not later than 72 hours after becoming aware — and will have to preserve any information that may assist the investigation. The duty is not a general one to report every offence under the Act: it is scoped to offences involving the entity's own service or network, in the determined categories.
Once section 54 is proclaimed, the clock will run from the time the entity becomes "aware" that its service or network is involved — not from the time the offence was committed. The primary standard is reporting without undue delay; 72 hours is the outer marker where reporting that quickly is feasible. "Awareness" in this context means actual knowledge, although courts may in future consider whether wilful blindness — deliberately avoiding acquiring knowledge of an offence — constitutes awareness for purposes of the provision.
What Must Be Reported
- Offences in the categories determined under section 54(2), where the entity's own electronic communications service or network is involved in the commission of the offence.
- The report will have to be made to the SAPS in the prescribed form, without undue delay and, where feasible, not later than 72 hours after becoming aware.
- The entity will have to preserve any information that may assist in the investigation of the offence.
- Once in force, failure to comply will itself be an offence, punishable by a fine not exceeding R50,000 — the section does not provide for imprisonment.
Once in force, the section 54 reporting obligation will create a practical need for businesses to implement incident detection and response capabilities. If a business cannot detect that its service or network is involved in a cyber offence, it cannot report without undue delay — let alone within the 72-hour outer marker. Even now, while section 54 awaits proclamation and POPIA section 22 is the only breach-notification duty in force, robust intrusion detection systems, security monitoring, and incident response procedures are not merely good security practice — they are prerequisites for legal compliance.
Penalties — Fines and Imprisonment
The Cybercrimes Act prescribes significant penalties for the offences it creates. Section 19 sets out the sentencing framework, and the maximum penalty depends on the category of offence — with the most serious offences carrying no fixed statutory cap at all.
For contraventions of sections 2(1) and 2(2) (unlawful access), 3(3) and 7(2), a court may impose a fine or imprisonment for a period not exceeding five years, or both. For contraventions of sections 3(1) and 3(2) (unlawful interception), 4(1) (software or hardware tools), 5(1) (interference with data or a computer program), 6(1) (interference with a storage medium or computer system) and 7(1) (passwords and access codes), the maximum rises to a fine or imprisonment not exceeding ten years, or both. Aggravated offences against restricted computer systems under section 11(1) carry a fine or imprisonment not exceeding fifteen years, or both.
Cyber fraud (section 8), cyber forgery and uttering (section 9), cyber extortion (section 10) and the aggravated offences under section 11(2) carry no fixed statutory maximum. Instead, the court imposes a sentence under section 276 of the Criminal Procedure Act within its penal jurisdiction — in practice, these offences are sentenced in the same way as their common-law equivalents of fraud, forgery and extortion.
A practical point that is often overlooked: where the offender had privileged access to the affected computer system — a system administrator, employee or service provider with elevated rights — section 19(6) requires the court to impose direct imprisonment unless substantial and compelling circumstances justify a different sentence.
Section 54 was excluded from the Act’s 1 December 2021 commencement and is not yet in force; it will require ECSPs and financial institutions to report qualifying offences to the SAPS (within 72 hours, on pain of a fine of up to R50,000) only once the President proclaims a commencement date. Once in force, failure to comply with that reporting and preservation duty will itself be an offence: an electronic communications service provider or financial institution that fails to report a qualifying offence without undue delay (and, where feasible, within 72 hours) would be liable on conviction to a fine not exceeding R50,000 — the section does not provide for imprisonment. While this fine may appear modest relative to the potential harm caused by a cyber incident, the reputational damage and regulatory scrutiny that follow a failure to report can be far more significant.
Penalty Summary (Section 19)
Where the offender had privileged access to the system, direct imprisonment must be imposed unless substantial and compelling circumstances justify otherwise (s 19(6)).
Electronic Communications Service Providers — Specific Obligations
The Act places specific obligations on electronic communications service providers (ECSPs) as defined in the Electronic Communications Act 36 of 2005. These obligations recognise the role that ECSPs play as intermediaries in the digital ecosystem and their capacity to detect, prevent, and assist in the investigation of cybercrimes.
Beyond the section 54 reporting duty (which is not yet in force — it was excluded from the Act’s 1 December 2021 commencement and awaits a presidential proclamation), ECSPs must comply with preservation and disclosure orders issued by courts. A preservation order under section 39 of the Act requires the ECSP to preserve specified data for a period of up to 90 days, which may be extended by a further 90 days. The data must be kept intact and protected from alteration or deletion. This creates a practical need for ECSPs to maintain data retention capabilities and incident response procedures that enable them to preserve data rapidly upon receipt of a court order.
A disclosure order under section 42 compels the ECSP to disclose specified data to an authorised person. The ECSP must comply within the timeframe specified in the order. Non-compliance with a preservation or disclosure order is a criminal offence.
The practical implications for SaaS providers and cloud service operators are significant. If your business provides services that involve the transmission, storage, or processing of data on behalf of others, you may qualify as an ECSP and be subject to these obligations. This should be factored into your service architecture, data retention policies, and the terms of your SaaS agreements.
Interaction with POPIA Breach Notification
A cybersecurity incident will frequently trigger obligations under both the Cybercrimes Act and POPIA simultaneously. Understanding the relationship between these two reporting regimes is essential for managing a cyber incident effectively and lawfully.
Under POPIA section 22 — the only breach-notification duty currently in force — where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, the responsible party must notify the Information Regulator and the affected data subjects "as soon as reasonably possible" after the discovery of the compromise. POPIA does not prescribe a fixed timeframe; the Information Regulator has indicated around 72 hours as guidance only. (The Cybercrimes Act section 54 report is a parallel obligation that will apply once section 54 is proclaimed — see below.)
The two regimes are complementary but distinct. POPIA requires notification to the Information Regulator and to affected data subjects, and focuses on the compromise of personal information — and it is the only one of the two currently in force. The Cybercrimes Act section 54 report to the SAPS focuses on the criminal offence, but is a parallel obligation that will apply only once section 54 is proclaimed. A single incident — such as a ransomware attack that results in the exfiltration of personal data — may, once section 54 is in force, trigger both obligations simultaneously.
Breach-Reporting Obligations
POPIA (Section 22) — in force now
- Report to: Information Regulator + data subjects
- Timeframe: "As soon as reasonably possible" (Regulator indicates ~72 hours as guidance only)
- Trigger: Compromise of personal information
- Applies to: All responsible parties
- Status: The only breach-notification duty currently in force
Cybercrimes Act (Section 54) — not yet in force
- Report to: SAPS
- Timeframe: Without undue delay (where feasible, within 72 hours)
- Trigger: Own service/network involved in a determined offence category
- Applies to: ECSPs and financial institutions
- Status: A parallel obligation that will apply once section 54 is proclaimed (excluded from the 1 December 2021 commencement)
Businesses should develop incident response plans that address both reporting regimes simultaneously. The plan should identify the responsible persons for each notification stream, establish templates for the required notifications, and ensure that the investigative and forensic processes preserve evidence for potential criminal prosecution while complying with POPIA's transparency requirements. For more on structuring data processing agreements that address breach notification obligations, see our dedicated guide.
Practical Cybersecurity Compliance Steps for Businesses
Compliance with the Cybercrimes Act is not merely about understanding the criminal offences it creates — it requires businesses to implement practical measures that reduce the risk of cyber incidents and ensure compliance with reporting obligations when incidents occur.
1Develop an Incident Response Plan
Create a documented incident response plan that identifies the team responsible for managing cyber incidents, establishes escalation procedures, defines the criteria for determining whether an incident triggers reporting obligations, and includes pre-drafted notification templates. Test the plan regularly through tabletop exercises and simulated incidents.
2Implement Technical Security Controls
Deploy intrusion detection and prevention systems, maintain firewalls and endpoint protection, implement multi-factor authentication across all critical systems, encrypt sensitive data at rest and in transit, and establish secure backup and recovery procedures. These measures not only reduce the likelihood of a successful attack but also demonstrate reasonable security practices in the event of litigation.
3Train Employees
Conduct regular cybersecurity awareness training for all staff, including training on identifying phishing attempts, social engineering attacks, and business email compromise. Employees are typically the weakest link in any security chain, and regular training significantly reduces the risk of successful attacks.
4Review Contracts and Insurance
Review your contracts with service providers, SaaS vendors, and cloud infrastructure providers to ensure that they adequately address cybersecurity obligations, breach notification procedures, and liability allocation. Consider obtaining cyber insurance to mitigate the financial impact of a cyber incident, including costs associated with forensic investigation, legal advice, notification, and business interruption.
5Establish Data Preservation Capabilities
If your business may qualify as an ECSP, ensure that you have the technical capability to preserve data in response to a preservation order within the timeframes prescribed by the Act. This includes maintaining audit logs, system logs, and access records in a manner that allows them to be isolated and preserved on short notice.
Reporting a Cybercrime — The Process
When a cybercrime occurs — whether your business is the victim, or you become aware of a cybercrime affecting your systems or users — the following practical steps should be followed.
Step 1: Contain the incident. Take immediate steps to prevent further unauthorised access or data loss. This may include isolating affected systems, revoking compromised credentials, and blocking malicious IP addresses. Critically, do not shut down or reformat affected systems before forensic evidence has been preserved.
Step 2: Preserve evidence. Engage a forensic specialist to create forensic images of affected systems and preserve relevant logs. The chain of custody must be maintained to ensure that the evidence is admissible in criminal proceedings. Document all actions taken from the moment the incident was discovered.
Step 3: Report to the SAPS. File a criminal complaint at your nearest police station. The SAPS has established specialised units for the investigation of cybercrimes. You can also report cybercrimes to the SAPS Cybercrime Unit directly. Provide as much detail as possible, including the nature of the offence, the systems affected, the suspected method of attack, and any evidence that has been preserved.
Step 4: Notify the Information Regulator (if personal data is compromised). If the incident involves the compromise of personal information, notify the Information Regulator and affected data subjects as required by POPIA section 22. The notification must describe the nature of the compromise, the personal information involved, the measures taken to address the breach, and the steps the data subject can take to protect themselves.
Step 5: Engage legal counsel. A cybersecurity incident involves complex legal considerations spanning criminal law, data protection, contract law, and potentially insurance law. Early engagement of experienced legal counsel ensures that the response is managed in a way that protects the business's interests, preserves legal privilege where appropriate, and meets all regulatory obligations.
Professional Guidance on Cybersecurity Compliance
The Cybercrimes Act imposes real obligations with criminal consequences for non-compliance. Whether you need help developing an incident response plan, reviewing your contractual arrangements with technology providers, or responding to an active cyber incident, prompt and informed legal advice is essential.
MJ Kotze Inc advises businesses on cybersecurity compliance, breach notification procedures, and the contractual frameworks needed to manage cyber risk. For tailored advice, please contact us.
Need Cybersecurity Legal Advice? Contact MJ Kotze Inc
From incident response to regulatory compliance, our team provides practical legal guidance for businesses navigating the Cybercrimes Act and related obligations.
Related Topics
Software & Technology Law
Comprehensive hub covering SaaS agreements, IP, data protection, and more
AI Governance & Regulation
Understanding the emerging framework for artificial intelligence in South Africa
Data Processing Agreements
Structuring POPIA-compliant operator agreements with breach notification clauses
For the businesses we act for
The Keystone Workspace
The attorney-designed platform the businesses we act for use to run their contracts, e-signatures and company secretarial work in one place.
Why you can trust this: Martin Kotze has been an admitted Attorney of the High Court of South Africa, registered Conveyancer, and Notary Public since 2014, practising from Pretoria. The firm is regulated by the Legal Practice Council under firm registration 17444.
This guide is general information, not legal advice for your specific matter.